繁体   English   中英

Alpine 3.3,Python 2.7.11,urllib2导致SSL:CERTIFICATE_VERIFY_FAILED

[英]Alpine 3.3, Python 2.7.11, urllib2 causing SSL: CERTIFICATE_VERIFY_FAILED

我有这个小Dockerfile

FROM alpine:3.3
RUN apk --update add python
CMD ["python", "-c", "import urllib2; response = urllib2.urlopen('https://www.python.org')"]

使用docker build -t alpine-py/01 .构建它docker build -t alpine-py/01 . 然后使用docker run -it --rm alpine-py/01创建以下输出

Traceback (most recent call last):
  File "<string>", line 1, in <module>
  File "/usr/lib/python2.7/urllib2.py", line 154, in urlopen
    return opener.open(url, data, timeout)
  File "/usr/lib/python2.7/urllib2.py", line 431, in open
    response = self._open(req, data)
  File "/usr/lib/python2.7/urllib2.py", line 449, in _open
    '_open', req)
  File "/usr/lib/python2.7/urllib2.py", line 409, in _call_chain
    result = func(*args)
  File "/usr/lib/python2.7/urllib2.py", line 1240, in https_open
    context=self._context)
  File "/usr/lib/python2.7/urllib2.py", line 1197, in do_open
    raise URLError(err)
urllib2.URLError: <urlopen error [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)>

昨天我被最近的OpenSSL 1.0.2g版本所困扰,导致py-cryptograpy无法编译。 幸运的是,来自py-cryptography的人在几个小时后在PyPI上发布了一个新版本。 问题是OpenSSL中的一个函数获得了一个新的签名。

这可能是相关的还是我错过了什么?

您需要安装ca-certificates才能验证公共CA的签名证书:

FROM alpine:3.3
RUN apk --no-cache add python ca-certificates
CMD ["python", "-c", "import urllib2; response = urllib2.urlopen('https://www.python.org')"]

您需要升级Alpine,因为libssl需要使用补丁进行升级

FROM alpine:3.3
RUN apk -U upgrade && \
    apk -U add python ca-certificates && \
    update-ca-certificates
CMD ["python", "-c", "import urllib2; response = urllib2.urlopen('https://www.python.org')"]

apk -U升级将升级这些:

  • libcrypto1.0(1.0.2e-r0 - > 1.0.2g-r0)
  • libssl1.0(1.0.2e-r0 - > 1.0.2g-r0)

暂无
暂无

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM